PT-2024-18395 · Mattermost · Mattermost
Eva Sarafianou
·
Published
2024-02-29
·
Updated
2025-05-12
·
CVE-2024-1888
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Mattermost versions prior to v8.1.9
Description
Mattermost fails to check the
invite guest permission when inviting guests of other teams to a team, allowing a member with permissions to add other members but not to add guests to add a guest to a team as long as the guest was already a guest in another team of the server.Recommendations
For versions prior to v8.1.9, update to version v8.1.9 or later to resolve the issue.
As a temporary workaround, consider restricting the use of the
invite guest permission to minimize the risk of exploitation.Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mattermost